
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@attribloom/mcp
Advanced tools
Attribloom MCP server · operate your tenant via the read-only management API
Model Context Protocol server for Attribloom. It lets Claude Code, Claude Desktop, Cursor, and any other MCP client read your tenant's affiliate data and get integration guidance, using a tenant API key.
Attribloom is affiliate attribution and commission tracking for iOS apps (StoreKit 2 and App Store Server Notifications v2) and Shopify stores. Two of the seven tools need no key at all, so an agent can learn how to integrate before you have an account.
claude mcp add attribloom --env ATTRIBLOOM_API_KEY=eak_live_... -- npx -y @attribloom/mcp
mcpServers JSON{
"mcpServers": {
"attribloom": {
"command": "npx",
"args": ["-y", "@attribloom/mcp"],
"env": {
"ATTRIBLOOM_API_KEY": "eak_live_..."
}
}
}
}
Settings, then MCP, then Add new server:
attribloomcommandenv ATTRIBLOOM_API_KEY=eak_live_... npx -y @attribloom/mcpATTRIBLOOM_API_KEY=eak_live_... npx -y @attribloom/mcp --http
Serves Streamable HTTP at http://127.0.0.1:3000/mcp. Set PORT and HOST to override.
Get a key from the Attribloom dashboard: Settings, then API keys. Keys are shown once and are scoped read-only.
| Tool | Scope required | Description |
|---|---|---|
get_started_guidance | none | Public onboarding steps |
connect_store_guidance | none | How to connect Shopify or an iOS app |
whoami | any key | Verify the key and show tenant plus scopes |
list_campaigns | read:campaigns | List campaigns and commission rules |
campaign_readout | read:conversions + read:commissions | Conversions and matured commission summary |
list_payouts | read:payouts | List payouts |
payout_eligibility | read:payouts | Per-affiliate available balance vs threshold |
Money mutations (approving an affiliate, creating a campaign, approving a payout) stay in the Attribloom dashboard and are intentionally not exposed here. This server is read-only by design.
Every figure returned comes from the real ledger. There are no estimated or projected numbers.
| Variable | Required | Default | Description |
|---|---|---|---|
ATTRIBLOOM_API_KEY | for data tools | none | Tenant API key from Dashboard, Settings, API keys |
ATTRIBLOOM_BASE_URL | no | https://api.attribloom.com | Management API base URL |
PORT | no | 3000 | HTTP transport port |
HOST | no | 127.0.0.1 | HTTP transport host |
Without a key the server still starts and the two guidance tools work. The data tools return a clear "API key required" message rather than failing silently.
| Scope | Tools |
|---|---|
read:campaigns | list_campaigns |
read:conversions | campaign_readout |
read:commissions | campaign_readout |
read:payouts | list_payouts, payout_eligibility |
User: connect my Attribloom account
whoami: Tenant: Acme Corp (tenant-123), scopes: read:campaigns, read:conversions, read:commissions, read:payouts
User: what campaigns do I have?
list_campaigns: Summer Launch, Web Purchase funnel
User: how is it performing?
campaign_readout: 42 conversions, $1,240 USD matured commission
User: who can be paid out?
payout_eligibility: 3 affiliates above threshold
attribloom-mcp # stdio transport (default; what MCP clients spawn)
attribloom-mcp --http # Streamable HTTP transport
attribloom-mcp --version
attribloom-mcp --help
npm install
npm run build
npm test
MIT
FAQs
Attribloom MCP server · operate your tenant via the read-only management API
We found that @attribloom/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.